| Name | CVE-2007-3215 |
| Description | PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-1315-1 |
| Debian Bugs | 429179, 429190, 429191, 429192, 429193, 429194, 429195, 429196, 429197, 504253, 504255 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| libphp-phpmailer (PTS) | bullseye | 6.2.0-2 | fixed |
| bookworm | 6.6.3-1 | fixed | |
| forky, sid, trixie | 6.9.3-1 | fixed | |
| wordpress (PTS) | bullseye | 5.7.11+dfsg1-0+deb11u1 | fixed |
| bullseye (security) | 5.7.14+dfsg1-0+deb11u1 | fixed | |
| bookworm, bookworm (security) | 6.1.6+dfsg1-0+deb12u1 | fixed | |
| trixie | 6.8.1+dfsg1-1 | fixed | |
| forky, sid | 6.8.3+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| egroupware | source | (unstable) | (not affected) | |||
| flyspray | source | sarge | (not affected) | |||
| flyspray | source | etch | (not affected) | |||
| flyspray | source | (unstable) | 0.9.8-12 | 429191, 429195 | ||
| glpi | source | etch | (not affected) | |||
| glpi | source | (unstable) | 0.68.3.2-1 | 429192 | ||
| ipplan | source | (unstable) | 4.85-2 | 429193 | ||
| knowledgeroot | source | etch | (not affected) | |||
| knowledgeroot | source | (unstable) | 0.9.8.2-2 | 429196 | ||
| libphp-phpmailer | source | etch | 1.73-2etch1 | DSA-1315-1 | ||
| libphp-phpmailer | source | (unstable) | 1.73-4 | high | 429179 | |
| mahara | source | lenny | 1.0.4-3 | |||
| mahara | source | (unstable) | 1.0.5-2 | 504253 | ||
| moodle | source | (unstable) | 1.8.2-2 | 429190 | ||
| owl-dms | source | etch | (not affected) | |||
| owl-dms | source | (unstable) | 0.94-2 | 429197 | ||
| phpgroupware | source | etch | (not affected) | |||
| phpgroupware | source | (unstable) | 0.9.16.012+dfsg-9 | medium | 504255 | |
| wordpress | source | etch | (not affected) | |||
| wordpress | source | (unstable) | 2.2.1-1 | 429194 |
[etch] - flyspray <not-affected> (Vulnerable code not)
[sarge] - flyspray <not-affected> (Vulnerable code not included)
[etch] - knowledgeroot <not-affected> (Vulnerable code not used)
[etch] - owl-dms <not-affected> (Vulnerable code not used)
[etch] - glpi <not-affected> (Vulnerable code not used)
[etch] - wordpress <not-affected> (Vulnerable code not present)
[etch] - phpgroupware <not-affected> (bug #504255; Vulnerable code not used)
- egroupware <not-affected> (bug #504283; Vulnerable code not used)